安全检查清单
- 工具 Schema 应精简且明确。
- 执行工具前先校验解析后的参数。
- 使用工具名称白名单;拒绝未知工具。
- 为外部调用添加超时和重试。
- 记录调用 ID、工具名称和校验失败信息。
请求校验示例(TypeScript + Zod)
失败处理策略
如果校验失败:- 不要执行工具。
- 在下一轮模型请求中返回受控错误信息。
- 让模型使用修正后的参数重试。
Documentation Index
Fetch the complete documentation index at: /docs/llms.txt
Use this file to discover all available pages before exploring further.
校验工具参数、加强执行安全,并避免模型执行不安全操作。
import { z } from "zod";
const WeatherArgs = z.object({
city: z.string().min(1),
});
function executeToolCall(name: string, rawArgs: string) {
if (name !== "get_weather") {
throw new Error(`Unsupported tool: ${name}`);
}
const parsed = WeatherArgs.parse(JSON.parse(rawArgs));
return getWeather(parsed.city);
}